Built-in Policy
Chute's built-in policies are DIRECT, REJECT with its variants, and PROXY. DIRECT sends the request to the host directly. REJECT refuses it; the variants below refuse it in different ways.
In addition, when a [Tailscale] section is configured, the built-in identifier TAILSCALE becomes available. See Tailscale Configuration for details.
All of them can be used in rules and policy groups directly. You can also define an alias in the proxy section.
REJECT Variants
| Policy | Behavior |
|---|---|
REJECT |
Refuses the connection. A request through the HTTP proxy gets a refusal response, or the error page when show-error-page-for-reject is on. |
REJECT-NO-DROP |
Same as REJECT, and never escalated to REJECT-DROP (see below). |
REJECT-DROP |
Never answers: the connection is held silently until it times out, and UDP is dropped. |
REJECT-TINYGIF, REJECT-IMG |
Answers 200 with a 1×1 GIF. |
REJECT-DICT |
Answers 200 with an empty JSON object {}. |
REJECT-ARRAY |
Answers 200 with an empty JSON array []. |
REJECT-200 |
Answers 200 with an empty body. |
REJECT-VIDEO |
Answers 200 with a blank MP4. |
The 200 answers need a plain HTTP/1 request — plain HTTP, or HTTPS decrypted by MitM. When none arrives within 3 seconds, the connection is closed as with REJECT. Except for REJECT-DROP, rejected UDP is answered with an ICMP port unreachable.
Answers Chute generates itself — Map Local, a script's response, and the answers and error page of URL Rewrite and the REJECT policies — follow HTTP: the answer to a HEAD request is the header alone, with the Content-Length a GET would get, and an answer with status 204, 205 or 304 carries neither a body nor a Content-Length.
Like Surge, a host refused by REJECT, REJECT-TINYGIF or REJECT-IMG more than 50 times within 30 seconds is handled as REJECT-DROP for the next 30 seconds, so a client retrying in a tight loop stops getting instant answers. REJECT-NO-DROP and the other variants are never escalated.
PROXY
For compatibility with Shadowrocket, PROXY can be used in rules and policy groups without being defined. It stands for the policy selected for Global mode — the one you pick from the global policy list — and follows that choice as it changes. If the configuration defines its own policy or group named Proxy (in any letter case), that definition is used instead. When nothing can be selected, the configuration still loads with a notice, and connections that reach PROXY are refused.
Alias
[Proxy]
On = direct
Off = reject
Then you can use 'On' and 'Off' as a policy name in rule and policy group. Any other parameter on such a line is ignored, with a notice in the log.